123 vulnerabilities across 15 products scored HIGH or above on August 11, 2026.
- π΄ CRITICAL: 20
- π HIGH: 103
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-71558 (apache/fory) β F1: exploitable β functional, AAS: 10.9 β 12.9 (HIGH β CRITICAL). Originally in 2026-08-07 bulletin.
- [UPGRADED] CVE-2026-62873 (microsoft/microsoft_365_admin_center) β F1: theoretical β poc, AAS: 9.1 β 11.6 (HIGH β HIGH). Originally in 2026-08-07 bulletin.
- [UPGRADED] CVE-2026-65507 (sergey/aiwu) β F1: exploitable β functional, AAS: 10.9 β 12.9 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-5430 (wso2/api_control_plane) β F1: theoretical β poc, AAS: 10.7 β 13.2 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-34191 (apache/apr-util) β F1: exploitable β functional, AAS: 10.5 β 12.5 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-28139 (wpdreams/ajax_search_lite) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2025-15039 (wso2/wso2_identity_server) β F1: theoretical β itw, AAS: 9.9 β 13.9 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-65583 (apache/cxf) β F1: exploitable β functional, AAS: 9.9 β 11.9 (HIGH β HIGH). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-68079 (apache/cxf) β F1: theoretical β poc, AAS: 9.6 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-48168 (mervinpraison/praisonai) β F1: exploitable β functional, AAS: 10.8 β 12.8 (HIGH β CRITICAL). Originally in 2026-08-05 bulletin.
- [UPGRADED] CVE-2026-70478 (flowiseai/flowise) β F1: theoretical β poc, AAS: 9.9 β 12.4 (HIGH β CRITICAL). Originally in 2026-08-04 bulletin.
π΄ [CRITICAL] adobe/coldfusion_2025
6 CVEs | CVSS 3.1: 8.8 | AAS 14.4
cpe:2.3:a:adobe:coldfusion_2025:*:*:*:*:*:*:*:*
Adobe ColdFusion 2025 is affected by six vulnerabilities disclosed in APSB26-90, including multiple critical-severity flaws with a maximum CVSS score of 8.8. The most severe issue is an incorrect authorization vulnerability that allows arbitrary code execution without user interaction, and there is evidence of active exploitation in the wild. While the vulnerable component is restricted to administrative network zones by default, organizations running ColdFusion 2025 should treat this as an urgent priority.
Administrators should review the vendor advisory at helpx.adobe.com/security/products/coldfusion/apsb26-90.html and apply the available patches immediately, prioritizing any internet-facing or shared-hosting ColdFusion instances given confirmed in-the-wild exploitation.
- π΄ CVE-2026-71387 (CVSS 3.1: 8.8)
- π΄ CVE-2026-71386 (CVSS 3.1: 8.8)
- π CVE-2026-21279 (CVSS 3.1: 8.2)
- π CVE-2026-21273 (CVSS 3.1: 8.7)
- π CVE-2026-48440 (CVSS 3.1: 8.1)
- π CVE-2026-34635 (CVSS 3.1: 8.4)
π΄ [CRITICAL] microsoft/visual_studio_code
6 CVEs | CVSS 3.1: 8.8 | AAS 14.2
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Microsoft Visual Studio Code is affected by six vulnerabilities, including multiple critical-severity issues with a maximum CVSS score of 8.8. The most severe is a network-exploitable OS command injection flaw that allows an unauthorized attacker to execute arbitrary code, and there is confirmed exploitation in the wild. All development teams and organizations with VS Code deployed across their environments should treat this as high priority.
Administrators should update Visual Studio Code to the latest available version immediately and review the Microsoft Security Response Center advisory at msrc.microsoft.com for full details on all six CVEs, paying particular attention to any extensions or network-facing configurations that may increase exposure.
- π΄ CVE-2026-69320 (CVSS 3.1: 8.8)
- π CVE-2026-70336 (CVSS 3.1: 8.8)
- π CVE-2026-59113 (CVSS 3.1: 8.8)
- π CVE-2026-69278 (CVSS 3.1: 7.8)
- π CVE-2026-58650 (CVSS 3.1: 7.8)
- π CVE-2026-69306 (CVSS 3.1: 8.2)
π΄ [CRITICAL] adobe/adobe_commerce
4 CVEs | CVSS 3.1: 9.1 | AAS 13.8
cpe:2.3:a:adobe:adobe_commerce:*:*:*:*:*:*:*:*
Adobe Commerce is affected by four vulnerabilities disclosed in APSB26-92, including multiple critical-severity flaws with a maximum CVSS score of 9.1. The most severe is an incorrect authorization vulnerability enabling privilege escalation and unauthorized access to sensitive resources without user interaction, and proof-of-concept exploit code is publicly available. Organizations running Adobe Commerce or Magento Open Source storefronts should consider this an urgent risk given the potential for unauthorized administrative access to e-commerce platforms.
Administrators should review the vendor advisory at helpx.adobe.com/security/products/magento/apsb26-92.html and apply patches as soon as possible, particularly for any internet-facing storefronts where exploitation could lead to data theft or transaction manipulation.
- π΄ CVE-2026-71362 (CVSS 3.1: 9.1)
- π CVE-2026-48413 (CVSS 3.1: 8.7)
- π CVE-2026-48416 (CVSS 3.1: 7.5)
- π CVE-2026-48415 (CVSS 3.1: 7.6)
π΄ [CRITICAL] craftcms/cms
4 CVEs | CVSS 4.0: 9.3 | AAS 13.5
cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*
Craft CMS versions 5.0.0-RC1 through 5.10.5 are affected by four vulnerabilities, including multiple critical-severity issues with a maximum CVSS 4.0 score of 9.3. The most severe is an incorrect authorization flaw that allows control panel users with view-only permissions to permanently modify category structures, and proof-of-concept exploit code is publicly available for these issues. Organizations running Craft CMS 5.x should treat this as a high-priority update, particularly in multi-user environments where granular permission controls are relied upon for content integrity.
Administrators should upgrade to Craft CMS 5.10.6 or later and review the security advisories linked from the vendor GitHub page at github.com/craftcms/cms/security for full details on all four CVEs and any interim mitigations.
- π΄ CVE-2026-72785 (CVSS 4.0: 9.3)
- π CVE-2026-72781 (CVSS 4.0: 8.7)
- π CVE-2026-72778 (CVSS 4.0: 8.7)
- π CVE-2026-72779 (CVSS 4.0: 8.7)
π΄ [CRITICAL] eosphoros-ai/db-gpt
1 CVE | CVSS 4.0: 9.3 | AAS 13.2
cpe:2.3:a:eosphoros-ai:db-gpt:*:*:*:*:*:*:*:*
DB-GPT version 0.8.1 is affected by a critical unauthenticated path traversal vulnerability with a CVSS 4.0 score of 9.3, and there is confirmed exploitation in the wild. The flaw allows remote attackers to write arbitrary files to any server location by injecting directory traversal sequences into the user_id HTTP header of the file-upload endpoint, enabling code execution through mechanisms such as Python startup hooks or cron directories. Any organization running DB-GPT should treat this as an emergency, particularly since no authentication is required to exploit the vulnerability.
Administrators should immediately restrict network access to DB-GPT instances, check for signs of compromise such as unexpected files in system directories, and monitor the vendor GitHub repository at github.com/eosphoros-ai/DB-GPT for a patched release.
- π΄ CVE-2026-73034 (CVSS 4.0: 9.3)
π΄ [CRITICAL] seaweedfs/seaweedfs
3 CVEs | CVSS 3.1: 9.8 | AAS 13.1
cpe:2.3:a:seaweedfs:seaweedfs:*:*:*:*:*:*:*:*(< 4.24)
SeaweedFS versions prior to 4.24 are affected by three vulnerabilities, including multiple critical-severity flaws with a maximum CVSS score of 9.8. The most severe is an unauthenticated IAM access issue where the filer exposes gRPC IAM endpoints without authentication when the JWT signing key is not configured, allowing any network-reachable attacker to create users, mint access keys, and gain full S3 administrative control. Proof-of-concept exploit code is publicly available, making this a high-priority concern for any organization using SeaweedFS in production.
Administrators should upgrade to SeaweedFS 4.24 or later immediately, ensure that jwt.filer_signing.key is properly configured in all deployments, and audit IAM accounts and access keys for any unauthorized entries that may indicate prior compromise.
- π΄ CVE-2026-72920 (CVSS 3.1: 9.8)
- π CVE-2026-72921 (CVSS 3.1: 8.1)
- π CVE-2026-73080 (CVSS 3.1: 9.3)
π΄ [CRITICAL] papersgpt/papersgpt-for-zotero
1 CVE | CVSS 4.0: 9.4 | AAS 13.0
cpe:2.3:a:papersgpt:papersgpt-for-zotero:*:*:*:*:*:*:*:*
PapersGPT for Zotero version 0.6.1 is affected by a critical remote code execution vulnerability with a CVSS 4.0 score of 9.4, and there is confirmed exploitation in the wild. The flaw stems from unsanitized LLM responses being passed directly to window.eval(), allowing attackers to execute arbitrary JavaScript in Zotero’s chrome-privileged context through prompt injection in PDFs, man-in-the-middle interception of API requests, or a malicious custom LLM endpoint, potentially enabling full file system access and process execution. Researchers and academic institutions using this Zotero plugin should treat this as an immediate concern given the multiple low-complexity attack vectors.
Users should disable or uninstall PapersGPT for Zotero until a patched version is available, monitor the vendor GitHub repository at github.com/papersgpt/papersgpt-for-zotero for updates, and review systems for any indicators of compromise such as unexpected file modifications or outbound connections.
- π΄ CVE-2026-73032 (CVSS 4.0: 9.4)
π΄ [CRITICAL] microsoft/microsoft_365_apps_for_enterprise
9 CVEs | CVSS 3.1: 8.8 | AAS 12.6
cpe:2.3:a:microsoft:microsoft_365_apps_for_enterprise:*:*:*:*:*:*:*:*
Microsoft 365 Apps for Enterprise is affected by nine vulnerabilities, including multiple critical-severity flaws with a maximum CVSS score of 8.8, and there is confirmed exploitation in the wild. The most severe is a stack-based buffer overflow in Microsoft Office Excel that allows an attacker to execute arbitrary code locally, likely triggered by opening a malicious document. Given the widespread deployment of Microsoft 365 across virtually all enterprise environments, this patch cycle should be treated as an urgent priority.
Administrators should apply the latest Microsoft 365 updates immediately through standard update channels, review the Microsoft Security Response Center advisories at msrc.microsoft.com for details on all nine CVEs, and remind users to exercise caution with unsolicited Excel files and Office documents from untrusted sources.
- π΄ CVE-2026-68817 (CVSS 3.1: 7.8)
- π΄ CVE-2026-68810 (CVSS 3.1: 7.8)
- π΄ CVE-2026-68815 (CVSS 3.1: 7.8)
- π΄ CVE-2026-65807 (CVSS 3.1: 8.8)
- π CVE-2026-68816 (CVSS 3.1: 7.8)
- π CVE-2026-68811 (CVSS 3.1: 7.8)
- π CVE-2026-70329 (CVSS 3.1: 8.8)
- π CVE-2026-70311 (CVSS 3.1: 7.8)
- π CVE-2026-68812 (CVSS 3.1: 7.8)
π΄ [CRITICAL] freecad/freecad
2 CVEs | CVSS 3.1: 8.5 | AAS 12.6
cpe:2.3:a:freecad:freecad:*:*:*:*:*:*:*:*(< 1.1.2)
FreeCAD versions prior to 1.1.2 are affected by two critical vulnerabilities with a maximum CVSS score of 8.5, and there is confirmed exploitation in the wild. The most severe is a path traversal flaw in the PropertyFileIncluded restore function that allows a crafted .FCStd project file to write attacker-controlled content to arbitrary locations on the file system when opened, potentially leading to code execution. Engineering teams, manufacturers, and any organizations using FreeCAD for 3D modeling should treat this as an urgent update, as exploitation requires only that a user open a malicious project file.
Users should upgrade to FreeCAD 1.1.2 or later immediately, exercise extreme caution with .FCStd files received from untrusted sources, and review systems for any signs of compromise such as unexpected files written outside normal project directories.
- π΄ CVE-2026-73234 (CVSS 3.1: 7.8)
- π CVE-2026-73233 (CVSS 4.0: 8.5)
π΄ [CRITICAL] yeswiki/yeswiki
1 CVE | CVSS 3.1: 9.8 | AAS 12.4
cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*(< 4.6.4)
YesWiki versions prior to 4.6.4 are affected by a critical unauthenticated SQL injection vulnerability with a CVSS score of 9.8, and proof-of-concept exploit code is publicly available. The flaw exists in the Bazar form-import path and allows any unauthenticated visitor on a default YesWiki installation to inject arbitrary SQL and read the full database, including user password hashes. Any organization running a YesWiki instance should treat this as an emergency given the trivial exploitation requirements and the direct exposure of credential data.
Administrators should upgrade to YesWiki 4.6.4 immediately, rotate all user passwords following the update, and review database access logs for any indicators of prior exploitation. The full advisory is available at github.com/YesWiki/yeswiki/security/advisories/GHSA-jwvv-qr7q-cv8j.
- π΄ CVE-2026-46670 (CVSS 3.1: 9.8)
π΄ [CRITICAL] microsoft/windows
78 CVEs | CVSS 3.1: 9.8 | AAS 12.3
cpe:2.3:a:microsoft:windows:*:*:*:*:*:*:*:*
Microsoft Windows is affected by 78 vulnerabilities in this patch cycle, including multiple critical-severity flaws with a maximum CVSS score of 9.8, and there is confirmed exploitation in the wild. The breadth of affected components spans core OS services including the iSCSI Target Service, with vulnerabilities ranging from denial of service to remote code execution, making this one of the largest Windows security updates this cycle. Every organization running any supported version of Windows should treat this as the highest-priority patching event.
Administrators should deploy the August 2026 cumulative updates immediately across all Windows endpoints and servers, prioritize internet-facing and critical infrastructure systems, and review the full list of advisories at msrc.microsoft.com for details on all 78 CVEs to identify any components requiring additional mitigation or configuration changes.
- π΄ CVE-2026-65681 (CVSS 3.1: 7.5)
- π΄ CVE-2026-65775 (CVSS 3.1: 7.8)
- π CVE-2026-65791 (CVSS 3.1: 9.8)
- π CVE-2026-62878 (CVSS 3.1: 9.8)
- π CVE-2026-62893 (CVSS 3.1: 9.8)
- π CVE-2026-65671 (CVSS 3.1: 7.8)
- π CVE-2026-65774 (CVSS 3.1: 7.8)
- π CVE-2026-65679 (CVSS 3.1: 8.1)
- π CVE-2026-42976 (CVSS 3.1: 7.8)
- π CVE-2026-65787 (CVSS 3.1: 7.8)
- π CVE-2026-62711 (CVSS 3.1: 7.8)
- π CVE-2026-61365 (CVSS 3.1: 7.8)
- π CVE-2026-62710 (CVSS 3.1: 7.8)
- π CVE-2026-49179 (CVSS 3.1: 8.8)
- π CVE-2026-62797 (CVSS 3.1: 7.8)
- π CVE-2026-62816 (CVSS 3.1: 8.8)
- π CVE-2026-62823 (CVSS 3.1: 8.8)
- π CVE-2026-62824 (CVSS 3.1: 8.8)
- π CVE-2026-61930 (CVSS 3.1: 7.8)
- π CVE-2026-62696 (CVSS 3.1: 7.8)
- π CVE-2026-62747 (CVSS 3.1: 7.8)
- π CVE-2026-62822 (CVSS 3.1: 8.8)
- π CVE-2026-62795 (CVSS 3.1: 8.8)
- π CVE-2026-62785 (CVSS 3.1: 8.8)
- π CVE-2026-62815 (CVSS 3.1: 9.8)
- π CVE-2026-62784 (CVSS 3.1: 8.8)
- π CVE-2026-62790 (CVSS 3.1: 8.8)
- π CVE-2026-62818 (CVSS 3.1: 8.8)
- π CVE-2026-62800 (CVSS 3.1: 8.8)
- π CVE-2026-54984 (CVSS 3.1: 7.8)
- π CVE-2026-59132 (CVSS 3.1: 7.5)
- π CVE-2026-65814 (CVSS 3.1: 7.8)
- π CVE-2026-62732 (CVSS 3.1: 7.8)
- π CVE-2026-65789 (CVSS 3.1: 8.1)
- π CVE-2026-65786 (CVSS 3.1: 7.8)
- π CVE-2026-62894 (CVSS 3.1: 7.8)
- π CVE-2026-62877 (CVSS 3.1: 7.8)
- π CVE-2026-62761 (CVSS 3.1: 7.8)
- π CVE-2026-62820 (CVSS 3.1: 8.1)
- π CVE-2026-62817 (CVSS 3.1: 8.8)
- π CVE-2026-62803 (CVSS 3.1: 7.8)
- π CVE-2026-62792 (CVSS 3.1: 8.1)
- π CVE-2026-62807 (CVSS 3.1: 7.8)
- π CVE-2026-62819 (CVSS 3.1: 8.1)
- π CVE-2026-65790 (CVSS 3.1: 7.8)
- π CVE-2026-62777 (CVSS 3.1: 7.8)
- π CVE-2026-62768 (CVSS 3.1: 7.8)
- π CVE-2026-62758 (CVSS 3.1: 7.8)
- π CVE-2026-62735 (CVSS 3.1: 7.8)
- π CVE-2026-62741 (CVSS 3.1: 7.8)
- π CVE-2026-62885 (CVSS 3.1: 7.8)
- π CVE-2026-61349 (CVSS 3.1: 7.8)
- π CVE-2026-62812 (CVSS 3.1: 7.8)
- π CVE-2026-62781 (CVSS 3.1: 8.1)
- π CVE-2026-62778 (CVSS 3.1: 8.1)
- π CVE-2026-62700 (CVSS 3.1: 7.8)
- π CVE-2026-62776 (CVSS 3.1: 7.8)
- π CVE-2026-62755 (CVSS 3.1: 7.8)
- π CVE-2026-62717 (CVSS 3.1: 7.8)
- π CVE-2026-61937 (CVSS 3.1: 7.8)
- π CVE-2026-61932 (CVSS 3.1: 7.8)
- π CVE-2026-62752 (CVSS 3.1: 7.8)
- π CVE-2026-62754 (CVSS 3.1: 7.8)
- π CVE-2026-62770 (CVSS 3.1: 7.8)
- π CVE-2026-61367 (CVSS 3.1: 7.8)
- π CVE-2026-61364 (CVSS 3.1: 7.8)
- π CVE-2026-59127 (CVSS 3.1: 7.8)
- π CVE-2026-62701 (CVSS 3.1: 7.8)
- π CVE-2026-61925 (CVSS 3.1: 7.8)
- π CVE-2026-62707 (CVSS 3.1: 7.8)
- π CVE-2026-62712 (CVSS 3.1: 7.8)
- π CVE-2026-62719 (CVSS 3.1: 7.8)
- π CVE-2026-61926 (CVSS 3.1: 7.8)
- π CVE-2026-62692 (CVSS 3.1: 7.8)
- π CVE-2026-61353 (CVSS 3.1: 7.8)
- π CVE-2026-62889 (CVSS 3.1: 8.1)
- π CVE-2026-62890 (CVSS 3.1: 7.8)
- π CVE-2026-66799 (CVSS 3.1: 7.8)
π΄ [CRITICAL] truelockmc/streambert
2 CVEs | CVSS 3.1: 10.0 | AAS 12.3
cpe:2.3:a:truelockmc:streambert:*:*:*:*:*:*:*:*(< 2.5.0)
Streambert versions prior to 2.5.0 are affected by two critical vulnerabilities with a maximum CVSS score of 10.0, and proof-of-concept exploit code is publicly available. The most severe is an improper executable path validation flaw in the run-download IPC handler that allows a compromised renderer process to execute arbitrary local binaries with the application’s full privileges, representing a complete compromise of the Electron app’s security boundary. Any users or organizations running Streambert for video streaming and downloading should update immediately.
Users should upgrade to Streambert 2.5.0 or later, available at github.com/truelockmc/streambert/releases/tag/2.5.0, and review systems for any signs of unauthorized process execution that may indicate prior exploitation.
- π΄ CVE-2026-48056 (CVSS 3.1: 10.0)
- π CVE-2026-48046 (CVSS 4.0: 9.3)
π΄ [CRITICAL] n8n-io/n8n
4 CVEs | CVSS 4.0: 8.9 | AAS 12.2
cpe:2.3:a:n8n-io:n8n:*:*:*:*:*:*:*:*
n8n versions prior to 2.32.1 (and prior to 2.31.5 on the LTS branch) are affected by four vulnerabilities, including multiple critical-severity flaws with a maximum CVSS 4.0 score of 8.9, and proof-of-concept exploit code is publicly available. The most severe is an account takeover vulnerability in the Token Exchange Embed Login feature, where the service fails to verify that email claims are validated or that trusted key role ceilings are enforced, allowing an attacker with access to a token from a configured trusted issuer to authenticate as any local account. Organizations using n8n for workflow automation should treat this as a high-priority update, particularly those with embed login or external authentication configured.
Administrators should upgrade to n8n 2.32.1 or 2.31.5 immediately, review authentication logs for any suspicious token-based logins, and audit trusted key configurations. Full details are available at github.com/n8n-io/n8n/security/advisories/GHSA-8342-988q-86cr.
- π΄ CVE-2026-72772 (CVSS 4.0: 8.9)
- π CVE-2026-72767 (CVSS 4.0: 8.7)
- π CVE-2026-72766 (CVSS 4.0: 8.2)
- π CVE-2026-72765 (CVSS 4.0: 8.7)
π΄ [CRITICAL] wg-easy/wg-easy
1 CVE | CVSS 3.1: 9.9 | AAS 12.2
cpe:2.3:a:wg-easy:wg-easy:*:*:*:*:*:*:*:*
wg-easy version 15.3.0 is affected by a critical OS command injection vulnerability with a CVSS score of 9.9, and proof-of-concept exploit code is publicly available. The flaw allows any user with the clients.create permission to inject arbitrary WireGuard PostUp directives into the configuration file via newline characters in the client name field, resulting in arbitrary command execution as root when wg-quick processes the configuration. Organizations using wg-easy to manage WireGuard VPN deployments should treat this as an urgent priority, as exploitation requires only basic authenticated access and yields full root compromise.
Administrators should restrict clients.create permissions to trusted users immediately, monitor the vendor GitHub repository at github.com/wg-easy/wg-easy for a patched release, and audit existing WireGuard configuration files for any suspicious PostUp or PostDown directives that may indicate prior exploitation.
- π΄ CVE-2026-72603 (CVSS 3.1: 9.9)
π΄ [CRITICAL] friendica/friendica
1 CVE | CVSS 3.1: 9.8 | AAS 12.1
cpe:2.3:a:friendica:friendica:*:*:*:*:*:*:*:*
Friendica through the 2026.08-dev branch is affected by a critical unauthenticated SQL injection vulnerability with a CVSS score of 9.8, and proof-of-concept exploit code is publicly available. The flaw exists in the photo-view order parameter, which is concatenated unescaped into a query via a bare PDO::query() call, enabling stacked statement injection that allows any unauthenticated remote attacker to read, modify, or delete the entire database. Any organization or individual hosting a Friendica instance should treat this as an emergency given the trivial exploitation requirements and total database compromise potential.
Administrators should restrict public access to Friendica instances until a patch is available, monitor the vendor GitHub repository at github.com/friendica/friendica for a security fix, and review database logs for any indicators of injection activity or unauthorized data access.
- π΄ CVE-2026-72550 (CVSS 3.1: 9.8)